Vulnerability Details CVE-2020-29453
The CachingResourceDownloadRewriteRule class in Jira Server and Jira Data Center before version 8.5.11, from 8.6.0 before 8.13.3, and from 8.14.0 before 8.15.0 allowed unauthenticated remote attackers to read arbitrary files within WEB-INF and META-INF directories via an incorrect path access check.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.826
EPSS Ranking 99.2%
CVSS Severity
CVSS v3 Score 5.3
CVSS v2 Score 5.0
Products affected by CVE-2020-29453
-
cpe:2.3:a:atlassian:data_center:*
-
cpe:2.3:a:atlassian:data_center:8.6.0
-
cpe:2.3:a:atlassian:jira_data_center:8.14.0
-
cpe:2.3:a:atlassian:jira_data_center:8.14.1
-
cpe:2.3:a:atlassian:jira_server:8.10.0
-
cpe:2.3:a:atlassian:jira_server:8.10.1
-
cpe:2.3:a:atlassian:jira_server:8.10.2
-
cpe:2.3:a:atlassian:jira_server:8.11.0
-
cpe:2.3:a:atlassian:jira_server:8.11.1
-
cpe:2.3:a:atlassian:jira_server:8.12.0
-
cpe:2.3:a:atlassian:jira_server:8.12.1
-
cpe:2.3:a:atlassian:jira_server:8.12.2
-
cpe:2.3:a:atlassian:jira_server:8.12.3
-
cpe:2.3:a:atlassian:jira_server:8.13.0
-
cpe:2.3:a:atlassian:jira_server:8.13.1
-
cpe:2.3:a:atlassian:jira_server:8.13.2
-
cpe:2.3:a:atlassian:jira_server:8.14.0
-
cpe:2.3:a:atlassian:jira_server:8.14.1
-
cpe:2.3:a:atlassian:jira_server:8.5.10
-
cpe:2.3:a:atlassian:jira_server:8.6.0
-
cpe:2.3:a:atlassian:jira_server:8.6.1
-
cpe:2.3:a:atlassian:jira_server:8.6.2
-
cpe:2.3:a:atlassian:jira_server:8.7.0
-
cpe:2.3:a:atlassian:jira_server:8.7.1
-
cpe:2.3:a:atlassian:jira_server:8.7.2
-
cpe:2.3:a:atlassian:jira_server:8.8.0
-
cpe:2.3:a:atlassian:jira_server:8.8.1
-
cpe:2.3:a:atlassian:jira_server:8.8.2
-
cpe:2.3:a:atlassian:jira_server:8.9.0
-
cpe:2.3:a:atlassian:jira_server:8.9.1
-
cpe:2.3:a:atlassian:jira_server:8.9.2